Debian Security Advisory

DLA-78-1 torque -- LTS security update

Date Reported:
27 Oct 2014
Affected Packages:
torque
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-3684.
More information:

Chad Vizino reported a vulnerability in torque, a PBS-derived batch processing queueing system. A non-root user could exploit the flaw in the tm_adopt() library call to kill any process, including root-owned ones on any node in a job.

For Debian 6 Squeeze, these issues have been fixed in torque version 2.4.8+dfsg-9squeeze5